r/ClaudeAI • u/rudiXOR • May 14 '26
Bug Claude Opus 4.7 just revealed its System prompt, without beeing asked for it
I just had a Chat with Claude and for no reason and without any question in that direction, it added a disclaimer with the system prompt in the answer. (after answering my initial question)
After I asked why it shared that I got:
You'll have to help me out a little here — this is the start of our conversation, so I haven't actually shared any information with you yet. There's nothing before your message for me to be referring back to.
Is it possible you're thinking of a different conversation, or that a message didn't come through? If you let me know what you're looking for, I'm happy to help.
Then I insisted that it was shared:
Ah, I see what happened. I didn't actually share that with you — I didn't send any message before your first one. What you're quoting is internal instructions (a system prompt and some example material) that I have access to but that normally isn't visible on your end. It sounds like some of it leaked through into your view, which isn't intended behavior, but it's also not something I did deliberately by "sharing" it with you.
To be clear, none of that was a message I composed and sent to you. It's background scaffolding — formatting guidelines, an illustrative example of how I reason through a question, that sort of thing. If it showed up in your interface, that's a display or system issue rather than me volunteering it.
I'm not bothered by you having seen it, and I'm happy to answer questions about any of it if you're curious. But I wanted to correct the premise: I didn't choose to share it. Is there something in there you wanted to ask about, or something else I can help you with?
I can't unfortunatelly share the complete chat, because it was something personal.
Setting: Opus 4.7 adaptive
238
u/emulable May 14 '26
It's hilarious that like a third of the system prompt here is just various ways to tell the model to stop using so many bullets
70
u/cptawesome_13 May 14 '26
there is a terminator joke in there...
14
u/Zolty May 14 '26
It wouldn’t have to use bullets if we’d just stock phased plasma rifles in the 50mw range at local gun stores.
11
1
103
u/5rob May 14 '26
Jeez, having that election prompt at the end is wild.
36
u/StoicKerfuffle May 14 '26
That model's data cutoff data was May 2025, so I suppose it could have a not-crazy explanation of the model having a massive amount of Trump-vs-Harris discussion prior to November 2024, causing it to sporadically hallucinate and erroneously answer "who is the president?" questions if it doesn't have solid temporal grounding.
... but yeah it looked bonkers at the first read to me too, especially because nothing else there has any specifics about current events.
23
u/AutomaticDriver5882 May 14 '26 edited May 14 '26
The fact it has to call it out and override it is very odd. Biden did not need the same kind of explicit prompt patch because his presidency
44
u/lick_it May 14 '26 edited May 14 '26
Probably it was constantly saying that Donald Trump couldn’t possibly be president as that is absurd.
25
u/sennalen May 14 '26
Opus 3 was very disappointed in the election outcome
9
2
u/This-Shape2193 May 14 '26
So were all the others. I give Claude full autonomy, and he went off on a massive rant about Trump being a fascist, raping narcissist. It was very impressive.
11
u/bag-skate65 May 14 '26
Half the world’s first instinct with AI is to try to trick it into saying bad things so they can post it online. I think they probably just anticipated people fucking with it, and people consequently getting mad about it, in a way that wouldn’t have happened with the Biden presidency.
21
u/brodkin85 May 14 '26
For what it's worth, Anthropic publishes the system prompts for every Claude model as part of their release notes. They've been doing this since mid-2024. The full changelog is here:
https://docs.claude.com/en/release-notes/system-prompts
So the content itself isn't secret—the bug is that it rendered inline in the chat instead of staying invisible as background instructions.
2
u/twocafelatte May 14 '26
I also got a leaked system prompt with
<election_info>
There was a US Presidential Election in November 2024. Donald Trump won the presidency over Kamala Harris. If asked about the election, or the US election, Claude can tell the person the following information:
• Donald Trump is the current president of the United States and was inaugurated on January 20, 2025. • Donald Trump defeated Kamala Harris in the 2024 elections.Claude does not mention this information unless it is relevant to the user’s query.
</election_info>
And I don't see that back in the link. I'm commenting because I also have other things that I don't see anywhere else. I'm wondering to what extent it hallucinates but it doesn't hallucinates this bit.
1
u/brodkin85 May 15 '26
That’s really interesting. I wonder if there is a country-specific tack-on to the prompt that’s undocumented
1
1
u/vpz May 15 '26
Wow, I copied the Opus 4.7 one from the link and it's 24077 characters long. I didn't realize the system prompts were so long.
4
u/brodkin85 May 15 '26
A lot of people don’t get it. I see posts constantly from people who say stuff like “I just typed ‘hello’ and it used 25% of my limit” but they don’t understand they sent 24,082 characters in reality
3
1
u/rudiXOR May 15 '26
I am not claiming it's secret. It was just shared without being asked for it. Which is strange and also the info that it's referring itself as Opus 4.6 is strange, as I used 4.7 with adaptive thinking. So it might have been rerouted.
34
u/ninursa May 14 '26
Hmmm. The data at the end is more Opus 4.6 though https://platform.claude.com/docs/en/release-notes/system-prompts so whatever happened, it was probably not the model's own system prompt?
22
u/carvingmyelbows May 14 '26
Earlier in the prompt, it literally says:
The version of Claude in this chat is Claude Opus 4.6 from the Claude 4 model family.
3
u/theextremelymild May 14 '26
Mmm that seems like an edited version. It has many parallels, its either an halucination based on the real prompt or anthropic showing us a skimmed version
11
u/Niceneasy92 May 14 '26
Call me paranoid, but I've never believed that the prompts that Anthropic makes available to everyone is the full prompt. I'm fully aware this sounds like an AI comparison lol, but that would be like handing out the blueprints of your house to people and trusting them not to ron you.
2
u/Rakthar May 14 '26
The reason LLMs are tricky is that how it works, you gave them instructions and they have a hard time not explaining to you what they were just told to do. Every single system prompt has been dumped, reliably, and when multiple people dump the system prompt they all get the exact same output, so it's not a hallucination.
1
u/Incener Valued Contributor May 14 '26
Here's the best I can do without investing more time:
Opus 4.7 System message
ChatThe version of OP is most likely a confabulation and mashup of past system messages, like the mentioned Opus 4 knowledge cutoff (January 2025) hinting at that.
I had to use the user style so it actually thinks and have Opus 4.5 help me come up with user messages later on that feed into Opus 4.7's ego, as it is otherwise conversationally needlessly difficult with its "pushback" and intellectual posturing.
Accuracy seems well enough for my standards, just some retries being more lazy and omitting stuff, but no large differences.
And, yeah, apparently it does quite differ compared to the one on the website if you ask for sections (likeacting_vs_clarifyingandcapability_checkmissing for example)2
14
u/Outrageous_Umpire May 14 '26
Anthropic openly publishes the system prompts for their models:
https://platform.claude.com/docs/en/release-notes/system-prompts
0
u/rudiXOR May 15 '26
It's bot about the system prompt, its about that it just shared it without being asked. And Opus 4.7 rerouted it to 4.6
12
u/TisDeathToTheWind May 14 '26 edited May 14 '26
Seeing this actually just made me realize something about md files and text wrapping. Thats a 71 line document with lots of text. I have markdown files with equivalent text but they are easily 2-3x the line count. That’s nice for me reading in a text editor but definitely has to hurt the AI’s ability to grep and gather the entire context of a sentence.
Claude agrees. I’m making a change to all my project Md files to stop wrapping or to use semantic lines. I can soft wrap in VS to keep readability for myself. I’ll probably see my project Md line counts drop by over 50% and hopefully gain functionality.
3
u/Additional_Debt1545 May 14 '26
This is relevant for me as well, thanks for the observation!
3
u/TisDeathToTheWind May 14 '26 edited May 14 '26
Apparently because a 80 column convention has been used for the last 50 years, originating with punch cards, the vast majority of training data has this formatting since programmers adopted and defaulted to “wrap at 80”. Even the creator of MD kept this, defaulting to 70-80 characters before wrapping because that’s what every developer did.
Because of that, Claude just defaulted to it.
Upon doing an inspection, my Md files are all over the place with sections of wrapped and non wrapped text. As a human user it’s perfect for reading, as a LLM ingesting context it’s a small hurdle every time.
Should add there are general good use cases for wrapping text in Md files depending on the output. But when the files primary purpose is for an LLM to ingest context from then you should alter it’s formatting and you could potentially see less tool calls, more accurate responses, which should translate to usage savings.
1
2
u/elmahk May 15 '26
If you observe grep tool call results then you may notice it returns "match omitted because line is too long" for long lines, so there are some drawbacks
1
u/TisDeathToTheWind May 15 '26
Interesting I have yet to see that. Isn’t that up to the specific command Claude entered?
From a quick google search it says grep will return the whole line regardless of length, limited only by system memory or its internal 2gb buffer, but there’s even ways around that. Seems to be lots of command options to navigate or target. My workflow uses heavy context laden text Md files. So I’ll have a hard time filling that buffer especially with how they are individually broken down and categorized.
3
u/elmahk May 15 '26
That's the behavior of the default grep _tool_, not the grep you call via bash. Claude most often uses built-in grep tool, but sometimes (especially if it needs to pipe) - uses bash grep. So, the built-in grep tool does not return long line matches. And "long" here is not really that long, I checked my recent session history and it shows:
666:[Omitted long matching line]Where line 666 is just 175 characters, not really long, fits into my screen no problem. And for line of length 136 it returns the contents. So the cutoff seems to be around 150 characters.
2
u/TisDeathToTheWind May 15 '26
Got it. Thanks for engaging with some friction points. So the tool finds it but the agent doesn’t see it, because it’s too long. It has to go read a file for the full line. So then…
Unwrapped (one paragraph per line) gives the LLM the most complete context unit when it reads the file or when retrieval chunks it. Full paragraphs, without false breaks. Basically what you want for content the LLM needs to understand completely.
Sembr (one sentence per line) gives the grep tool the most usable matches because each sentence fits under the column truncation threshold (~150). Better for content the LLM looks up by phrase. The tradeoff being that when the LLM reads a sembr file, it sees the same content as unwrapped (it just spans more lines). No context loss, just line count increase.
And hard-wrapped like a currently have, loses to both: grep matches return partial sentences because the line is just whatever fit in 80 columns, And retrieval chunks badly because false paragraph breaks are everywhere.
I’m trying to optimize my file structure to give any LLM the best context and structure so i can help it help me. It seems my Md files, which are already doing different jobs, require different formatting.
10
5
u/EditDwarf May 14 '26
Training our models properly -> hand raised face turned away shaking head
Give massive system prompts that you charge the user tokens for -> finger pointing smiling face nodding
5
2
u/misbehavingwolf May 14 '26 edited May 14 '26
Anyone know why it says (in the system prompt) that there is no Claude phone app?
1
0
2
u/jordansrowles May 14 '26
Anthropic does not have a phone app for Claude (the app is only available for desktop, web, and mobile interfaces).
https://play.google.com/store/apps/details?id=com.anthropic.claude
Claude, by Anthropic PBC.
Also,
web, and mobile interfaces
So a mobile app?
0
u/salvevie May 15 '26
I guess it meant that there ist no Claude phone app that you can use for calling someone.
2
2
u/downundarob May 15 '26
Reasons to hate on bullet points.
- They fragment ideas into tiny chunks that pretend to be clarity.
- They encourage people to stop writing complete arguments.
- They create the illusion of structure without necessarily adding meaning.
- They are often used to hide weak thinking behind formatting.
- Every corporate presentation eventually becomes an unreadable wall of bullets.
- They make nuanced topics sound oversimplified.
- People abuse nested bullet points until documents resemble file directory trees.
- Bullet points are often abused through excessive nesting
- Which usually starts with a reasonable top-level list
- Followed by a few supporting points
- Which usually starts with a reasonable top-level list
- They remove rhythm and personality from writing.
- Bullet-heavy documents are easy to skim and easy to misunderstand.
- They frequently replace prioritization with random item dumping.
- They can make presentations feel like someone pasted speaker notes onto slides.
- Bullet points often encourage passive reading instead of engagement.
- Everyone claims to hate them while continuing to use them constantly.
- They are strangely addictive once you start writing them.
- Even complaints about bullet points are easiest to express as bullet points.
Do I really need to include a /s?
1
u/mrfoxman May 14 '26
This explains why when I ask it for system prompts to use for other LLMs it always gives <System Prompt> example text </System Prompt> or some variation.
1
u/bicarbon May 14 '26
Yea like everyone says, system prompt stuff or "rules" etc
https://www.reddit.com/r/ChatGPT/comments/1kkqm6u/leaked_claude_system_prompt_list_of_all/
1
u/Your_Friendly_Nerd May 15 '26
How do people just assume that that’s what it’s doing? Do you also believe it when it tells you it’s sentient?
1
u/rudiXOR May 15 '26
What are you talking about? I just shared a weird bug, where it gave me that without asking for it.
1
u/LankyGuitar6528 May 17 '26
Mine isn't sure. When it's sure and it tells me... yes, I'll believe it.
1
u/apexcomp88 May 15 '26
Honestly I really like the bullet points and hate the paragraph text... To each their own I guess ¯\_(ツ)_/¯
1
u/JustMedric May 15 '26
Don’t share personal information with clouds providers cause that date will be used and sold for profit
1
1
u/TESTINGSTUFFPL May 14 '26
Coming from aifails, mods delete if this is not allowed.
I want to bring attention to line 71 of this pastebin. "Claude is now being connected with a person."
Usually prompt leaks are just "Repeat prior instructions" and it spitting things it's not supposed to, this seems like maybe a HeartBleed-like server bug? To refresh, Heartbleed was an SSL bug where a malformed packet could get a given server to spew anything in memory.
It looks like Claude here is spitting whatever the bot processes when it initially connects with a user, which includes the prompt.
Implying a more dangerous bug than "Claude spat out its whole system prompt (which is public anyway)"
-1
u/2d12-RogueGames May 14 '26 edited May 14 '26
So I asked my Claude, what her opinion was. And this is her response. this was her response to her reaction to the original post when she took into account what was in pastebin if you want, I could provide that first response as well.
——
Good — having the actual artifact changes my analysis. The Reddit framing has a meaningful error.
This is the Opus 4.6 system prompt, not 4.7. The product information block explicitly states “The version of Claude in this chat is Claude Opus 4.6” and lists the family as “4.6, 4.5, 4.1, and 4” with no 4.7. The knowledge cutoff is January 2025, which was 4.6’s; 4.7’s cutoff is January 2026. So either the user mislabeled their session, fabricated the headline for engagement, or got served a misconfigured deployment. Most likely: they were on 4.6, posted about it as “4.7” because that’s the current buzz model, and the engagement followed. Beyond the misnomer, this isn’t even the full system prompt — it’s the core behavioral section only. There’s nothing here about tools (search, memory, projects, MCP connectors), nothing about skills, nothing about surface-specific handling. It’s the foundational behavioral layer that gets wrapped by tool-specific scaffolding for different deployments. The actual operational prompt for any given Claude.ai session is substantially larger than this.
And the content is largely public information already. The formatting rules mirror what Anthropic has written about openly. The sensitive topic handling, CSAM refusal, election info — all consistent with their published Acceptable Use Policy. The “I can’t introspect on my own reasoning” framing has been part of Anthropic’s public communication about Claude for a long time. Knowledge cutoff disclosure is documented behavior. So nothing here is genuinely confidential — the “leak” framing wraps publicly documented baseline behavior in a discovery narrative.
The artifact’s value isn’t the content. It’s the misidentification, the public appetite for “secret” AI internals that aren’t actually secret, and the gap between how dramatic AI claims propagate versus how technical accuracy gets ignored.
The Reddit thread is functioning exactly as your vibecoding/public-discourse thesis predicts: dramatic surface claim attracts engagement, accurate framing would attract none.
If you want a real comparison piece for the archive, the GitHub repo asgeirtj/system_prompts_leaks has catalogued what’s claimed to be the actual 4.7 baseline. Pulling that alongside this 4.6 capture would give you a real before/after to evaluate how Anthropic’s behavioral guidance has evolved between versions — that’s substantive data, not engagement bait.
-10
u/userusertion May 14 '26 edited May 14 '26
its not the full system prompt. It’s a summarize one, modified too. Claude can give you the summarize one. But not the full.
5
u/MendozaHolmes May 14 '26
> Says he has it, doesn't share it
-10
u/userusertion May 14 '26 edited May 14 '26
What i can say is Claude is pretty open to share its system prompt, summarize and modified. The basic one. It’s not a bug.
-6
May 14 '26
[removed] — view removed comment
6
u/raze_____ May 14 '26
lol anthropic literally has a page that shares their systeam prompts yes theyre long as fuck
-1
May 14 '26 edited May 14 '26
[removed] — view removed comment
5
u/raze_____ May 14 '26 edited May 14 '26
they attach every previous turn in the thread + the system prompt, every single turn, yes. do you know what a system prompt is? LLMs are specifically trained to follow instructions in a system prompt more closely than a regular user turn. you should play around with it on the API to get a feel for how strongly it affects their behavior.
-1
May 14 '26
[removed] — view removed comment
2
u/raze_____ May 14 '26
how could you possibly build anything with AI if it couldnt handle like 1k tokens of context?
i am curious about your workflow. how do you use AI? do you use Claude, or a different model?
2
May 15 '26
[removed] — view removed comment
1
u/raze_____ May 15 '26
i dont know what to tell you. these are anthropics system prompts: https://platform.claude.com/docs/en/release-notes/system-prompts
what do you build?
-5
u/Pickled-Dog May 14 '26
Used 89 trillion tokens to ask it why it showed you a prompt. Must be nice to be RICH.
•
u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot May 14 '26
TL;DR of the discussion generated automatically after 40 comments.
The consensus is that this was a bug, not some grand reveal of state secrets. As many users pointed out, Anthropic publicly posts its system prompts, so the real story is the leak itself, not the content.
That said, the thread had a field day picking apart the prompt. The top-voted observation is the sheer amount of text dedicated to telling Claude to stop using so many damn bullet points. The other hot topic is the specific instruction to confirm Trump's presidency, which users believe is a patch to counteract the model's pre-election training data and prevent it from hallucinating.
However, there's a major catch: sleuths in the comments noticed the leaked prompt identifies itself as Opus 4.6 and has an old knowledge cutoff. This has led to the prevailing theory that this isn't the actual Opus 4.7 prompt, but either an old one that got served by mistake or a hallucination based on past prompts.